Set up Cloud Number Registry

This page explains how to set up Cloud Number Registry in your organization.

Before you begin

  1. Designate a project to use for Cloud Number Registry in this organization.
  2. Select the designated project to perform the steps in this guide.
  3. Verify that you have the permissions required to complete this guide.

Required roles

To get the permissions that you need to set up and manage Cloud Number Registry, ask your administrator to grant you the Cloud Number Registry IPAM Admin (roles/cloudnumberregistry.ipamAdmin) IAM role on your project. For more information about granting roles, see Manage access to projects, folders, and organizations.

You might also be able to get the required permissions through custom roles or other predefined roles.

Create an IPAM admin scope

When you create the IPAM admin scope, Cloud Number Registry performs setup tasks and identifies supported Compute Engine resources in your organization and adds them to a default registry book.

It can take up to 24 hours for all resources in the organization to be discovered. You can view the status of the IPAM admin scope to check if resource discovery is complete.

You can manage Cloud Number Registry through this default registry book, or you optionally create additional registry books to organize your resources.

If you get an error when you try to create an IPAM admin scope, see Troubleshooting.

Console

  1. In the Google Cloud console, go to the Cloud Number Registry page.

    Go to Cloud Number Registry

  2. Click the Manage tab.

  3. In the Manage IPAM admin scope panel, click Create IPAM admin scope.

The IPAM admin scope creation process starts. To check the progress of setup, view the status of the IPAM admin scope.

gcloud

Create the IPAM admin scope by using the gcloud alpha number-registry ipam-admin-scopes create command.

To check the progress of the Cloud Number Registry setup, view the status of the IPAM admin scope.

gcloud alpha number-registry ipam-admin-scopes create SCOPE_NAME \
    --enabled-addon-platforms=COMPUTE_ENGINE \
    --scopes=organizations/ORGANIZATION_ID \
    --location=global

Replace the following:

  • SCOPE_NAME: a name for the IPAM admin scope
  • ORGANIZATION_ID: the ID number of the organization that you want to manage.

View the status of the IPAM admin scope

The admin scope can have the following statuses during setup:

  • SETUP_IN_PROGRESS: setup has started but the discovery process isn't complete. It can take up to 24 hours for all existing resources in the organization to be discovered. However, any new resources that are created in the organization are discovered within a few minutes.
  • READY_TO_USE: the discovery process is complete and Cloud Number Registry is ready to use.

Console

  1. In the Google Cloud console, go to the Cloud Number Registry page.

    Go to Cloud Number Registry

  2. Click the Manage tab.

  3. In the Manage IPAM admin scope panel, view the State field.

gcloud

View details about the IPAM admin scope by using the gcloud alpha number-registry ipam-admin-scopes describe command.

gcloud alpha number-registry ipam-admin-scopes describe SCOPE_NAME \
    --location=global

Replace SCOPE_NAME with the IPAM admin scope name.

Troubleshooting

The following sections explain how to resolve issues that you might encounter when setting up Cloud Number Registry.

IPAM admin scope creation fails with ALREADY_EXISTS or INVALID_ARGUMENT error

If creation of the IPAM admin scope fails due to either of these errors, this is because an IPAM admin scope already exists in the project.

  • An IPAM admin scope with the same name already exists in this project:

    ALREADY_EXISTS: Resource 'projects/PROJECT_ID/locations/global/ipamAdminScopes/SCOPE_NAME'
    already exists.
    
  • An IPAM admin scope with a different name already exists in this project:

    INVALID_ARGUMENT: Violation in ipam_admin_scope.scopes: Scope
    organizations/ORGANIZATION_ID is already administered by another ipam admin scope
    'projects/PROJECT_ID/locations/global/ipamAdminScopes/EXISTING_SCOPE_NAME'
    

IPAM admin scope creation fails with FAILED_PRECONDITION error

If creation of an IPAM admin scope fails with the following error message, this means that this project hasn't been designated to use for Cloud Number Registry for this organization.

FAILED_PRECONDITION: There is no existing registry for 'projects/PROJECT_ID in scope
organizations/ORGANIZATION_ID'

To resolve this issue, do the following:

  1. Check if Cloud Number Registry is already set up for this organization in another project.

  2. If Cloud Number Registry isn't set up for this organization, check if a project is already designated for Cloud Number Registry in this organization.

  3. If no project is designated, ask your organization's administrator to designate a project for use with Cloud Number Registry or grant you access to do so.

What's next